Cybercrime is any criminal activity that involves a computer or network — either as the tool used to commit the crime or as the target of the crime. It can be committed by individuals, organised criminal groups, or even nation-states.
The CMA is the primary UK legislation governing cybercrime. It defines three main offences (Sections 1, 2 and 3), with a further offence added by the Police and Justice Act 2006 (Section 3A):
Intentionally accessing a computer system without permission — even if no data is taken or damaged. This includes:
Key point: The access must be intentional — accidentally seeing another user's screen does not satisfy this offence.
Section 1 plus the intent to commit a further offence (e.g., blackmail, fraud, theft). The further offence does not need to have been committed — intent is sufficient.
Deliberately altering, damaging, or erasing data or programs without permission. Includes:
Added by the Police and Justice Act 2006. Makes it illegal to create or distribute tools designed for use in cyberattacks — even if no attack has occurred. Includes:
Malicious software designed to damage, disrupt, or gain unauthorised access. Includes viruses, worms, Trojans, spyware, adware.
CMA Section 3Malware that encrypts the victim's files and demands payment for the decryption key. Often targets hospitals, businesses, and individuals.
CMA Section 3Fraudulent emails or messages that trick users into revealing passwords, credit card numbers, or other sensitive information by impersonating trusted organisations.
Section 1 + fraud lawsDistributed Denial of Service — flooding a server with traffic from many computers (botnet) until it becomes unavailable to legitimate users.
CMA Section 3Manipulating people into revealing confidential information or granting access — e.g., impersonating IT support to obtain a password.
Fraud + Section 1Systematically trying every possible password or key until the correct one is found. Can be performed offline against captured password hashes.
CMA Section 1Technical measures:
Human/procedural measures:
| Section | Offence | Example | Max Sentence |
|---|---|---|---|
| S.1 | Unauthorised access | Logging into someone's email | 2 years |
| S.2 | Unauthorised access with intent | Hacking to commit fraud | 5 years |
| S.3 | Unauthorised modification | Installing ransomware | 10 years |
| S.3A | Making/supplying attack tools | Selling malware kits | 10 years |
6 questions · instantly marked · Cambridge 9618 standard
| Term | Definition |
|---|
10 questions · 10 marks · 10 minutes